QuestionError In Dump Cshell.dll

Posts 1–7 of 7 · Page 1 of 1
Error In Dump Cshell.dll
I'm tired of trying To Dump Cshell.dll And Take Address
i download loadlib and open it in Game folder
put when i want to attach it in OllyDbg i didn't find loadlib process !
screen :

When i used other way :-
File>open>Loadlibrary.exe
i didn't found "view" dictionary
Screen :

what should i do i want to have CrossFire Address
27265561_852413381633977_1072593674_o.png92 KB · 8 downloads
Dude, use PETools and dump CShell from LoadLib
Quote Originally Posted by vaisefud3 View Post
Dude, use PETools and dump CShell from LoadLib
Thanks man its wark

- - - Updated - - -

Quote Originally Posted by vaisefud3 View Post
Dude, use PETools and dump CShell from LoadLib
do you Know any forum here which i can know how to get the offset of any adress ?
Quote Originally Posted by Mero203512 View Post
Thanks man its wark

- - - Updated - - -



do you Know any forum here which i can know how to get the offset of any adress ?
If you're looking for an address, go to the place of the offset. For example: WeaponMgr can be found at the place where the ReloadAnimRatio offset is found... Try looking for classes, they really help.

- - - Updated - - -

Quote Originally Posted by vaisefud3 View Post
If you're looking for an address, go to the place of the offset. For example: WeaponMgr can be found at the place where the ReloadAnimRatio offset is found... Try looking for classes, they really help.
Later on i'll post some prints for you
Quote Originally Posted by vaisefud3 View Post
If you're looking for an address, go to the place of the offset. For example: WeaponMgr can be found at the place where the ReloadAnimRatio offset is found... Try looking for classes, they really help.

- - - Updated - - -



Later on i'll post some prints for you
can i have Your FB To Talk with you ?

- - - Updated - - -

Quote Originally Posted by vaisefud3 View Post
If you're looking for an address, go to the place of the offset. For example: WeaponMgr can be found at the place where the ReloadAnimRatio offset is found... Try looking for classes, they really help.

- - - Updated - - -



Later on i'll post some prints for you
Because i can't understand you
Quote Originally Posted by Mero203512 View Post
can i have Your FB To Talk with you ?

- - - Updated - - -



Because i can't understand you
PM me your skype

- - - Updated - - -

This is an example for finding BasicPlayerInfo:

Code:
0C8DAAC6   . 68 308C180D    PUSH CShell_d.0D188C30                   ;  ASCII "CharacterHiddenAlpha"
0C8DAACB   . 50             PUSH EAX
0C8DAACC   . E8 DF187300    CALL CShell_d.0D00C3B0
0C8DAAD1   . 83C4 08        ADD ESP,0x8
0C8DAAD4   . 3BC3           CMP EAX,EBX
0C8DAAD6   . 74 33          JE SHORT CShell_d.0C8DAB0B
0C8DAAD8   . 8B48 04        MOV ECX,DWORD PTR DS:[EAX+0x4]
0C8DAADB   . 8B51 04        MOV EDX,DWORD PTR DS:[ECX+0x4]
0C8DAADE   . 8B42 04        MOV EAX,DWORD PTR DS:[EDX+0x4]
0C8DAAE1   . 50             PUSH EAX
0C8DAAE2   . FF15 1427110D  CALL DWORD PTR DS:[0xD112714]
0C8DAAE8   . D95C24 24      FSTP DWORD PTR SS:[ESP+0x24]
0C8DAAEC   . A1 149E6B0E    MOV EAX,DWORD PTR DS:[0xE6B9E14]
0C8DAAF1   . D94424 24      FLD DWORD PTR SS:[ESP+0x24]
0C8DAAF5   . 8B0D 189E6B0E  MOV ECX,DWORD PTR DS:[0xE6B9E18]  << Make a pattern here, scan it in your hack and then make a pointer to this
0C8DAAFB   . 83C4 04        ADD ESP,0x4                                                   plus 0x2
0C8DAAFE   . 69C0 A8000000  IMUL EAX,EAX,0xA8
0C8DAB04   . D99C08 8800000>FSTP DWORD PTR DS:[EAX+ECX+0x88]
0C8DAB0B   > 8B4C24 30      MOV ECX,DWORD PTR SS:[ESP+0x30]
0C8DAB0F   . 3BCB           CMP ECX,EBX
0C8DAB11   . 74 0D          JE SHORT CShell_d.0C8DAB20
0C8DAB13   . 8B4424 34      MOV EAX,DWORD PTR SS:[ESP+0x34]
0C8DAB17   . 2BC1           SUB EAX,ECX
0C8DAB19   . C1F8 02        SAR EAX,0x2
0C8DAB1C   . 3BF8           CMP EDI,EAX
0C8DAB1E   . 72 06          JB SHORT CShell_d.0C8DAB26
0C8DAB20   > FFD5           CALL EBP
0C8DAB22   . 8B4C24 30      MOV ECX,DWORD PTR SS:[ESP+0x30]
0C8DAB26   > 8B14B9         MOV EDX,DWORD PTR DS:[ECX+EDI*4]
This is the code for Crossfire AL/BR

BASIC = FindPattern((DWORD)CShell, 0xFFFFFF,(PBYTE)BytePattern, Mask);
BASIC = *(DWORD*)(BASIC + 0x2);
BASIC = BASIC - CShell;
Quote Originally Posted by vaisefud3 View Post
PM me your skype

- - - Updated - - -

This is an example for finding BasicPlayerInfo:

Code:
0C8DAAC6   . 68 308C180D    PUSH CShell_d.0D188C30                   ;  ASCII "CharacterHiddenAlpha"
0C8DAACB   . 50             PUSH EAX
0C8DAACC   . E8 DF187300    CALL CShell_d.0D00C3B0
0C8DAAD1   . 83C4 08        ADD ESP,0x8
0C8DAAD4   . 3BC3           CMP EAX,EBX
0C8DAAD6   . 74 33          JE SHORT CShell_d.0C8DAB0B
0C8DAAD8   . 8B48 04        MOV ECX,DWORD PTR DS:[EAX+0x4]
0C8DAADB   . 8B51 04        MOV EDX,DWORD PTR DS:[ECX+0x4]
0C8DAADE   . 8B42 04        MOV EAX,DWORD PTR DS:[EDX+0x4]
0C8DAAE1   . 50             PUSH EAX
0C8DAAE2   . FF15 1427110D  CALL DWORD PTR DS:[0xD112714]
0C8DAAE8   . D95C24 24      FSTP DWORD PTR SS:[ESP+0x24]
0C8DAAEC   . A1 149E6B0E    MOV EAX,DWORD PTR DS:[0xE6B9E14]
0C8DAAF1   . D94424 24      FLD DWORD PTR SS:[ESP+0x24]
0C8DAAF5   . 8B0D 189E6B0E  MOV ECX,DWORD PTR DS:[0xE6B9E18]  << Make a pattern here, scan it in your hack and then make a pointer to this
0C8DAAFB   . 83C4 04        ADD ESP,0x4                                                   plus 0x2
0C8DAAFE   . 69C0 A8000000  IMUL EAX,EAX,0xA8
0C8DAB04   . D99C08 8800000>FSTP DWORD PTR DS:[EAX+ECX+0x88]
0C8DAB0B   > 8B4C24 30      MOV ECX,DWORD PTR SS:[ESP+0x30]
0C8DAB0F   . 3BCB           CMP ECX,EBX
0C8DAB11   . 74 0D          JE SHORT CShell_d.0C8DAB20
0C8DAB13   . 8B4424 34      MOV EAX,DWORD PTR SS:[ESP+0x34]
0C8DAB17   . 2BC1           SUB EAX,ECX
0C8DAB19   . C1F8 02        SAR EAX,0x2
0C8DAB1C   . 3BF8           CMP EDI,EAX
0C8DAB1E   . 72 06          JB SHORT CShell_d.0C8DAB26
0C8DAB20   > FFD5           CALL EBP
0C8DAB22   . 8B4C24 30      MOV ECX,DWORD PTR SS:[ESP+0x30]
0C8DAB26   > 8B14B9         MOV EDX,DWORD PTR DS:[ECX+EDI*4]
This is the code for Crossfire AL/BR

BASIC = FindPattern((DWORD)CShell, 0xFFFFFF,(PBYTE)BytePattern, Mask);
BASIC = *(DWORD*)(BASIC + 0x2);
BASIC = BASIC - CShell;
pm me skybe please : mero203512@hotmail.com
Posts 1–7 of 7 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us